We attended the recent VB 2016 conference to present our findings on the development and evolution of Locky ransomware. In that same presentation we also discussed an automation system designed by Fortiguard to extract its configuration and hunt for new variants. Locky-ly (*wink*), while improving the system we couldn't help but notice another new variant. Actually, aside from the encrypted file name extension change, there are no major developments from the ".odin" variant in this new variant. However, ...

Read More...